8.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the OTP, thereby bypassing multi-factor authentication.
AI Analysis
Authentication bypass vulnerability in the OTP Integration Kit for PingFederate due to improper HTTP method and state validation
Basic Information
ID
CVE-2025-27935
Source
Ping Identity
Published
Dec 4, 2025 at 20:38
Affected Product
Vendor
Ping Identity
Product
One-Time Passcode Integration Kit for PingFederate
Version
1.0
Affected Versions
Ping Identity One-Time Passcode Integration Kit for PingFederate 1.0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Ping Identity
Product
One-Time Passcode Integration Kit for PingFederate
Version
1.0